When you upload a file to a Teams channel or chat, Microsoft Defender for Microsoft 365 may quarantine it if it detects malicious content. You see a message in the Teams admin center stating the file is quarantined, and users cannot open or download it. This happens because Defender scans all files shared in Teams and blocks those that match threat signatures or policy rules. This article explains why Teams quarantines files, how to review and release them in the Teams admin center, and what to do if the quarantine persists.
Key Takeaways: Release Quarantined Files in Teams Admin Center
- Microsoft 365 Defender portal > Email & collaboration > Review > Quarantine: Locate and release files that Defender flagged in Teams.
- Teams admin center > Teams apps > Manage apps: Verify that file-sharing policies do not block the file type.
- SharePoint admin center > Active files: Check if the file is also quarantined in SharePoint, which Teams uses for storage.
Why Microsoft Teams Quarantines Files in the Teams Admin Center
Microsoft Teams stores all shared files in SharePoint Online and OneDrive for Business. When you upload a file to a channel or chat, Microsoft Defender for Microsoft 365 scans it in real time. If the scan detects a virus, malware, or a policy violation, Defender moves the file to quarantine. The quarantine isolates the file so it cannot harm users, but it also blocks access to the file for everyone in the team.
The Teams admin center shows a quarantine status for files that Microsoft 365 security flags. This status appears in the file properties or in the activity log. The quarantine action occurs automatically, and only an administrator with the right permissions can release the file. The release process requires you to access the Microsoft 365 Defender portal, not the Teams admin center itself. The Teams admin center only displays the status; the actual release action happens in Defender.
Several scenarios cause the quarantine. The file may contain a known malware signature. The file may exceed the size limit for scanning, and Defender quarantines it by default. The file may have a file type that your organization blocks in a file-sharing policy. The quarantine can also occur if the file fails a data loss prevention policy, such as a policy that blocks files with credit card numbers.
Where Quarantined Files Appear in the Teams Admin Center
The Teams admin center does not have a dedicated quarantine folder. Instead, you see quarantine status in the activity log or in the file details when you inspect a specific team. To find the quarantine status, you must use the Microsoft 365 Defender portal. The Teams admin center links to Defender for security-related tasks. The quarantine list in Defender shows the file name, the user who shared it, the detection time, and the reason for quarantine.
Steps to Release a Quarantined File in the Microsoft 365 Defender Portal
Releasing a quarantined file requires administrator permissions. You need to be a member of the Global Administrator, Security Administrator, or Quarantine Administrator role. Follow these steps to review and release the file.
- Open the Microsoft 365 Defender portal
Go to https://security.microsoft.com and sign in with your administrator account. - Navigate to the quarantine list
In the left navigation, select Email & collaboration, then Review, then Quarantine. This opens the quarantine list for all scanned content, including Teams files. - Filter for Teams files
In the quarantine list, select the filter icon. In the Workload drop-down, choose Teams. This shows only files quarantined from Teams. - Locate the quarantined file
Find the file by its name, the user who shared it, or the detection date. The list shows the file name and the reason for quarantine. - Select the file and choose Release
Click the check box next to the file, then click Release in the action bar. A confirmation dialog appears. Click Release again to confirm. - Verify the file is accessible in Teams
Go back to Teams and open the channel or chat where the file was shared. The file should now be available for download and viewing.
If the File Is Not in the Quarantine List
Sometimes the file is not in the Defender quarantine list because the quarantine happened in SharePoint instead. Teams stores files in SharePoint, and SharePoint has its own quarantine mechanism. Check the SharePoint admin center for the file.
- Open the SharePoint admin center
Go to https://admin.microsoft.com and sign in as an administrator. - Navigate to Active files
In the left navigation, select Show all, then SharePoint, then Active files. This shows all files in SharePoint, including those in Teams. - Search for the file
Use the search box to find the file by name. If the file is quarantined, its status shows as Quarantined. - Release the file from SharePoint
Select the file, click Release in the command bar, and confirm the action.
If Teams Still Shows the File as Quarantined After Release
Teams Shows a Quarantine Message for a File That Was Released
If you released the file but Teams still displays a quarantine message, the file may be cached in the Teams client. Clear the Teams cache to refresh the status. Close Teams, then delete the cache folder. On Windows, go to %appdata%\Microsoft\Teams and delete the Cache, Code Cache, and GPUCache folders. Restart Teams and check the file again.
Teams Blocks the File Type Even After Release
If the quarantine was caused by a file type policy, releasing the file does not help. The file type is blocked by your organization’s file-sharing policy. To allow the file type, an administrator must modify the policy. In the Teams admin center, go to Teams apps > Permission policies and check the allowed file types. Alternatively, check the SharePoint admin center for file type restrictions.
The File Is Still Quarantined Because It Contains Malware
If Defender detected actual malware, releasing the file will fail or the file will be re-quarantined immediately. In this case, do not release the file. Instead, delete the file from quarantine and ask the user to upload a clean version. To delete, select the file in the quarantine list and click Delete.
New Teams vs Microsoft 365 Defender: Where to Handle Quarantined Files
| Item | Teams Admin Center | Microsoft 365 Defender Portal |
|---|---|---|
| Primary function | Manage Teams policies and settings | Manage security threats and quarantined content |
| Shows quarantine status | Yes, in activity log and file details | Yes, in the quarantine list |
| Allows releasing files | No | Yes |
| Required role | Teams administrator | Global Administrator, Security Administrator, or Quarantine Administrator |
| Best for | Checking which files are affected | Releasing or deleting quarantined files |
Now you know how to find and release quarantined files in the Microsoft 365 Defender portal. Check the SharePoint admin center if the file is not in Defender. Always verify that the file is safe before releasing it. If the file contains malware, delete it instead. Use the quarantine list in Defender to monitor future detections and keep your Teams environment secure.